Server-Side Request Forgery in Plate Rich-Text Editor Affects AI and shadcn/ui
CVE-2026-65842
8.2HIGH
What is CVE-2026-65842?
The Plate rich-text editor, used in conjunction with AI and shadcn/ui, prior to version 53.3.2, contains a vulnerability that allows for server-side request forgery. This occurs when the component processes attacker-controlled HTML through the htmlToDocxBlob method, permitting it to fetch remote image URLs. The converter's ability to access internal network resources can lead to the inclusion of maliciously fetched image data within generated DOCX files. This can expose sensitive data and result in unauthorized access to internal systems, in addition to consuming server resources from the targeted attacks. The issue has been remediated in version 53.3.2.
Affected Version(s)
plate < 53.3.2
